The purpose of the tool is to provide a single tool to parse various artifacts that are either produced by the suspsect operating system or other systems that might have some logs retaining to the investigation.

The purpose of the tool is to provide a single tool to parse various artifacts that are either produced by the suspsect operating system or other systems that might have some logs retaining to the investigation.

−

==Currently Supported Formats==

+

==Currently Supported Input Modules==

−

* Windows Prefetch directory

+

The currently supported input modules (as of version 0.51 nightly build (20102608)) are:

Revision as of 13:05, 26 August 2010

Contents

log2timeline

log2timeline is designed as a framework for artifact timeline creation and analysis. The main purpose is to provide a single tool to parse various log files and artifacts found on suspect systems (and supporting systems, such as network equipment) and produce a body file that can be used to create a timeline, using tools such as mactime from TSK, for forensic investigators.

The tool is written in Perl for Linux but has been tested using Mac OS X (10.5.7 and 10.5.8). Parts of it should work natively in Windows as well (with ActiveState Perl installed).

Description

log2timeline takes a log file (or a directory) and parses it to produce a body file that can be imported into other tools for timeline analysis. The tool has both a modular based approach to the input file as well as the output file. The current version supports exporting the timeline in a body format readable by TSK's (The SleuthKit) mactime. log2timeline is build as a series of scripts, this one being the front-end, which uses other scripts to actually parse the log files (called format files). The tool is build to be easily extended for anyone that wants to create a new format or an output file.

As noted above the current supported output is the body format used by mactime. For further information about the ouptput format, please read Mactime Body Format. Other output formats can be easily created by the use of an output file. The output file can be set to output in a body format that needs to be imported into another tool for human readable format, or it can be implemented to print the timeline directly in a human readable format.

The tool is build using multiple so called format files, which are stored in the format folder. Each of those format files provide a single format that can be parsed, whether that is a log file or a directory containing some files that need to be parsed.

The purpose of the tool is to provide a single tool to parse various artifacts that are either produced by the suspsect operating system or other systems that might have some logs retaining to the investigation.

Currently Supported Input Modules

The currently supported input modules (as of version 0.51 nightly build (20102608)) are:

apache2_access - Parse the content of a Apache2 access log file

apache2_error - Parse the content of a Apache2 error log file

chrome - Parse the content of a Chrome history file

evt - Parse the content of a Windows 2k/XP/2k3 Event Log

evtx - Parse the content of a Windows Event Log File (EVTX)

exif - Extract metadata information from files using ExifTool

ff_bookmark - Parse the content of a Firefox bookmark file

firefox2 - Parse the content of a Firefox 2 browser history

firefox3 - Parse the content of a Firefox 3 history file

iehistory - Parse the content of an index.dat file containg IE history